Adversaries may gather credentials from the proc filesystem or /proc.

Tactics
TA0006

Sub-technique of
T1003


See: MITRE ATT&CK